Cybersecurity — 2026-04-10

Anthropic's Claude Mythos Discovers Thousands of Zero-Day Vulnerabilities Across Major Software

Anthropic revealed that its unreleased Claude Mythos Preview model autonomously identified thousands of zero-day vulnerabilities in every major operating system and web browser. Discoveries include a 27-year-old DoS flaw in OpenBSD's TCP SACK implementation and a 16-year-old FFmpeg H.264 vulnerability. Anthropic launched Project Glasswing to give defenders early access rather than releasing the model publicly, partnering with organizations responsible for critical infrastructure. The company said AI models have reached a level where they "can surpass all but the most skilled humans" at finding and exploiting software flaws.

Analysis
Anthropic's decision to restrict Mythos rather than release it publicly represents a new model for AI capability governance: partnership with defenders rather than open deployment. The discovery of bugs decades old in OpenBSD and FFmpeg demonstrates that AI-driven vulnerability research operates at a scale human auditors cannot match. Project Glasswing's implications for offensive cyber operations are the unspoken counterpart.
2 sources
  1. Anthropic's Claude Mythos Finds Thousands of Zero-Day Flaws Across Major Systems - The Hacker News
  2. Anthropic's new AI model finds and exploits zero-days across every major OS and browser - Help Net Security

View in full brief →

UNCLASSIFIED // OPEN SOURCE